1Z0-1123-25 exam dumps

1Z0-1123-25 practice question 86 of 150

Oracle Cloud Infrastructure 2025 Migration Architect Professional. Professional level, Oracle. Free question with the correct answer and a full explanation.

1Z0-1123-25 Question 86

Select 2

Your company is migrating a set of containerized microservices from an on-premises environment to Oracle Cloud Infrastructure (OCI). You plan to deploy these microservices to Oracle Container Engine for Kubernetes (OKE). The microservices store persistent data and manage sensitive information (e.g., certificates, API keys). Which two actions should you take to ensure a secure and reliable migration of these containerized workloads?

  1. A

    Use OCI Block Volumes or OCI File Storage for persistent data, and configure dynamic volume provisioning in your Kubernetes manifests.

  2. B

    Store all certificates and secrets as plain text in environment variables for quick application start-up.

  3. C

    Integrate your Kubernetes Secrets with OCI Vault to encrypt and manage sensitive information.

  4. D

    Persist application data on the local storage of each Kubernetes node for higher performance.

Show answer and explanation

Correct answers: A, C

Explanation

For production-grade containerized workloads in OKE, it� essential to use OCI-managed persistent volumes (e.g., Block Volumes or File Storage) and configure dynamic provisioning for stable data management. Sensitive information should not be stored in plain text or directly in container images, but instead managed securely using Kubernetes Secrets integrated with OCI Vault. This approach follows OCI best practices for security and reliability. Refer to the OCI Documentation (https://docs.oracle.com/en-us/iaas/Content/ContEng/Concepts/contengoverview.htm) and Kubernetes documentation on persistent storage and secret management for more details.

  • A. Correct.

    Correct. OCI Block Volumes and OCI File Storage are recommended for persistent storage in OKE. Dynamic provisioning automates volume creation and management in Kubernetes.

  • B. Incorrect.

    Incorrect. Storing secrets in plain text environment variables is insecure. It poses a high risk, as anyone with access to environment variables can read these sensitive values.

  • C. Correct.

    Correct. Integrating Kubernetes Secrets with OCI Vault is a best practice for securing secrets at rest and leveraging OCI's managed encryption.

  • D. Incorrect.

    Incorrect. Local storage on Kubernetes nodes is ephemeral and not suitable for long-term persistence. If nodes fail or are replaced, data is lost.

Timed practice exam

Take a 1Z0-1123-25 practice test under exam conditions

50 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam